diff --git a/.gitignore b/.gitignore
index 470921f..a4d5620 100644
--- a/.gitignore
+++ b/.gitignore
@@ -24,3 +24,11 @@ clog
/wordpress-4.4.tar.gz
/wordpress-4.4.1.tar.gz
/wordpress-4.4.2.tar.gz
+/wordpress-4.5-RC1.tar.gz
+/wordpress-4.5.tar.gz
+/wordpress-4.5.1.tar.gz
+/wordpress-4.5.2.tar.gz
+/wordpress-4.5.3.tar.gz
+/wordpress-debian_patches_hello.patch
+/wordpress-4.6.tar.gz
+/wordpress-4.6.1.tar.gz
diff --git a/sources b/sources
index 5452e24..cde0dc9 100644
--- a/sources
+++ b/sources
@@ -1 +1 @@
-65d89263dad6154fdc8b747e9ef4e357 wordpress-4.4.2.tar.gz
+ca0b978fd702eac033830ca2d0784b79 wordpress-4.6.1.tar.gz
diff --git a/wordpress-4.4-noupdate.patch b/wordpress-4.4-noupdate.patch
deleted file mode 100644
index d02cf71..0000000
--- a/wordpress-4.4-noupdate.patch
+++ /dev/null
@@ -1,88 +0,0 @@
-diff -up wordpress/wp-admin/includes/admin-filters.php.orig wordpress/wp-admin/includes/admin-filters.php
---- wordpress/wp-admin/includes/admin-filters.php.orig 2015-10-15 00:35:24.000000000 +0200
-+++ wordpress/wp-admin/includes/admin-filters.php 2015-12-09 17:08:00.945112230 +0100
-@@ -100,7 +100,6 @@ add_action( 'profile_update', 'default_p
- add_action( 'admin_init', 'wp_plugin_update_rows' );
- add_action( 'admin_init', 'wp_theme_update_rows' );
-
--add_action( 'admin_notices', 'update_nag', 3 );
- add_action( 'admin_notices', 'maintenance_nag', 10 );
-
- add_filter( 'update_footer', 'core_update_footer' );
-diff -up wordpress/wp-admin/includes/class-wp-upgrader.php.orig wordpress/wp-admin/includes/class-wp-upgrader.php
---- wordpress/wp-admin/includes/class-wp-upgrader.php.orig 2015-11-16 03:47:25.000000000 +0100
-+++ wordpress/wp-admin/includes/class-wp-upgrader.php 2015-12-09 17:09:34.735571806 +0100
-@@ -2386,6 +2386,9 @@ class Core_Upgrader extends WP_Upgrader
- }
- }
-
-+ // RPM: nether allow core update
-+ return false;
-+
- // 1: If we're already on that version, not much point in updating?
- if ( $offered_ver == $wp_version )
- return false;
-@@ -2627,7 +2630,7 @@ class WP_Automatic_Updater {
- */
- public function is_disabled() {
- // Background updates are disabled if you don't want file changes.
-- if ( defined( 'DISALLOW_FILE_MODS' ) && DISALLOW_FILE_MODS )
-+ if ( !defined( 'DISALLOW_FILE_MODS' ) || DISALLOW_FILE_MODS )
- return true;
-
- if ( wp_installing() )
-diff -up wordpress/wp-admin/includes/update.php.orig wordpress/wp-admin/includes/update.php
---- wordpress/wp-admin/includes/update.php.orig 2015-12-09 17:08:00.946112235 +0100
-+++ wordpress/wp-admin/includes/update.php 2015-12-09 17:10:27.642831054 +0100
-@@ -251,7 +251,7 @@ function update_right_now_message() {
- $cur = get_preferred_from_update_core();
-
- if ( isset( $cur->response ) && $cur->response == 'upgrade' )
-- $msg .= '' . sprintf( __( 'Update to %s' ), $cur->current ? $cur->current : __( 'Latest' ) ) . ' ';
-+ $msg .= '';
- }
-
- /* translators: 1: version number, 2: theme name */
-diff -up wordpress/wp-includes/capabilities.php.orig wordpress/wp-includes/capabilities.php
---- wordpress/wp-includes/capabilities.php.orig 2015-11-29 03:27:18.000000000 +0100
-+++ wordpress/wp-includes/capabilities.php 2015-12-09 17:08:00.946112235 +0100
-@@ -308,7 +308,7 @@ function map_meta_cap( $cap, $user_id )
- // Disallow the file editors.
- if ( defined( 'DISALLOW_FILE_EDIT' ) && DISALLOW_FILE_EDIT )
- $caps[] = 'do_not_allow';
-- elseif ( defined( 'DISALLOW_FILE_MODS' ) && DISALLOW_FILE_MODS )
-+ elseif ( !defined( 'DISALLOW_FILE_MODS' ) || DISALLOW_FILE_MODS )
- $caps[] = 'do_not_allow';
- elseif ( is_multisite() && ! is_super_admin( $user_id ) )
- $caps[] = 'do_not_allow';
-@@ -326,7 +326,7 @@ function map_meta_cap( $cap, $user_id )
- case 'update_core':
- // Disallow anything that creates, deletes, or updates core, plugin, or theme files.
- // Files in uploads are excepted.
-- if ( defined( 'DISALLOW_FILE_MODS' ) && DISALLOW_FILE_MODS ) {
-+ if ( !defined( 'DISALLOW_FILE_MODS' ) || DISALLOW_FILE_MODS ) {
- $caps[] = 'do_not_allow';
- } elseif ( is_multisite() && ! is_super_admin( $user_id ) ) {
- $caps[] = 'do_not_allow';
-diff -up wordpress/wp-includes/update.php.orig wordpress/wp-includes/update.php
---- wordpress/wp-includes/update.php.orig 2015-12-06 16:44:27.000000000 +0100
-+++ wordpress/wp-includes/update.php 2015-12-09 17:12:09.038327895 +0100
-@@ -637,9 +637,6 @@ function _maybe_update_themes() {
- * @since 3.1.0
- */
- function wp_schedule_update_checks() {
-- if ( ! wp_next_scheduled( 'wp_version_check' ) && ! wp_installing() )
-- wp_schedule_event(time(), 'twicedaily', 'wp_version_check');
--
- if ( ! wp_next_scheduled( 'wp_update_plugins' ) && ! wp_installing() )
- wp_schedule_event(time(), 'twicedaily', 'wp_update_plugins');
-
-@@ -681,8 +678,6 @@ if ( ( ! is_main_site() && ! is_network_
- }
-
- add_action( 'admin_init', '_maybe_update_core' );
--add_action( 'wp_version_check', 'wp_version_check' );
--add_action( 'upgrader_process_complete', 'wp_version_check', 10, 0 );
-
- add_action( 'load-plugins.php', 'wp_update_plugins' );
- add_action( 'load-update.php', 'wp_update_plugins' );
diff --git a/wordpress-4.6-noupdate.patch b/wordpress-4.6-noupdate.patch
new file mode 100644
index 0000000..0038d1e
--- /dev/null
+++ b/wordpress-4.6-noupdate.patch
@@ -0,0 +1,103 @@
+diff -up wordpress/wp-admin/includes/admin-filters.php.rpm wordpress/wp-admin/includes/admin-filters.php
+--- wordpress/wp-admin/includes/admin-filters.php.rpm 2016-09-03 07:50:51.812312381 +0200
++++ wordpress/wp-admin/includes/admin-filters.php 2016-09-03 07:51:39.070577518 +0200
+@@ -106,7 +106,6 @@ add_action( 'profile_update', 'default_p
+ add_action( 'load-plugins.php', 'wp_plugin_update_rows', 20 ); // After wp_update_plugins() is called.
+ add_action( 'load-themes.php', 'wp_theme_update_rows', 20 ); // After wp_update_themes() is called.
+
+-add_action( 'admin_notices', 'update_nag', 3 );
+ add_action( 'admin_notices', 'maintenance_nag', 10 );
+
+ add_filter( 'update_footer', 'core_update_footer' );
+diff -up wordpress/wp-admin/includes/class-core-upgrader.php.rpm wordpress/wp-admin/includes/class-core-upgrader.php
+--- wordpress/wp-admin/includes/class-core-upgrader.php.rpm 2016-09-03 07:59:45.832367671 +0200
++++ wordpress/wp-admin/includes/class-core-upgrader.php 2016-09-03 07:59:50.160392833 +0200
+@@ -236,6 +236,9 @@ class Core_Upgrader extends WP_Upgrader
+ * @return bool True if we should update to the offered version, otherwise false.
+ */
+ public static function should_update_to_version( $offered_ver ) {
++ // RPM: nether allow core update
++ return false;
++
+ include( ABSPATH . WPINC . '/version.php' ); // $wp_version; // x.y.z
+
+ $current_branch = implode( '.', array_slice( preg_split( '/[.-]/', $wp_version ), 0, 2 ) ); // x.y
+diff -up wordpress/wp-admin/includes/class-wp-automatic-updater.php.rpm wordpress/wp-admin/includes/class-wp-automatic-updater.php
+--- wordpress/wp-admin/includes/class-wp-automatic-updater.php.rpm 2016-09-03 08:00:15.810540773 +0200
++++ wordpress/wp-admin/includes/class-wp-automatic-updater.php 2016-09-03 08:00:28.915616106 +0200
+@@ -31,7 +31,7 @@ class WP_Automatic_Updater {
+ */
+ public function is_disabled() {
+ // Background updates are disabled if you don't want file changes.
+- if ( defined( 'DISALLOW_FILE_MODS' ) && DISALLOW_FILE_MODS )
++ if ( !defined( 'DISALLOW_FILE_MODS' ) || DISALLOW_FILE_MODS )
+ return true;
+
+ if ( wp_installing() )
+diff -up wordpress/wp-admin/includes/translation-install.php.rpm wordpress/wp-admin/includes/translation-install.php
+--- wordpress/wp-admin/includes/translation-install.php.rpm 2016-05-22 20:01:30.000000000 +0200
++++ wordpress/wp-admin/includes/translation-install.php 2016-09-03 07:50:51.813312387 +0200
+@@ -181,7 +181,7 @@ function wp_download_language_pack( $dow
+ return $download;
+ }
+
+- if ( defined( 'DISALLOW_FILE_MODS' ) && DISALLOW_FILE_MODS ) {
++ if ( !defined( 'DISALLOW_FILE_MODS' ) || DISALLOW_FILE_MODS ) {
+ return false;
+ }
+
+@@ -224,7 +224,7 @@ function wp_download_language_pack( $dow
+ * @return bool Returns true on success, false on failure.
+ */
+ function wp_can_install_language_pack() {
+- if ( defined( 'DISALLOW_FILE_MODS' ) && DISALLOW_FILE_MODS ) {
++ if ( !defined( 'DISALLOW_FILE_MODS' ) || DISALLOW_FILE_MODS ) {
+ return false;
+ }
+
+diff -up wordpress/wp-admin/includes/update.php.rpm wordpress/wp-admin/includes/update.php
+--- wordpress/wp-admin/includes/update.php.rpm 2016-08-10 21:06:31.000000000 +0200
++++ wordpress/wp-admin/includes/update.php 2016-09-03 07:50:51.812312381 +0200
+@@ -271,7 +271,7 @@ function update_right_now_message() {
+ $cur = get_preferred_from_update_core();
+
+ if ( isset( $cur->response ) && $cur->response == 'upgrade' )
+- $msg .= '' . sprintf( __( 'Update to %s' ), $cur->current ? $cur->current : __( 'Latest' ) ) . ' ';
++ $msg .= '';
+ }
+
+ /* translators: 1: version number, 2: theme name */
+diff -up wordpress/wp-includes/capabilities.php.rpm wordpress/wp-includes/capabilities.php
+--- wordpress/wp-includes/capabilities.php.rpm 2016-06-30 03:02:29.000000000 +0200
++++ wordpress/wp-includes/capabilities.php 2016-09-03 07:50:51.812312381 +0200
+@@ -330,7 +330,7 @@ function map_meta_cap( $cap, $user_id )
+ // Disallow the file editors.
+ if ( defined( 'DISALLOW_FILE_EDIT' ) && DISALLOW_FILE_EDIT )
+ $caps[] = 'do_not_allow';
+- elseif ( defined( 'DISALLOW_FILE_MODS' ) && DISALLOW_FILE_MODS )
++ elseif ( !defined( 'DISALLOW_FILE_MODS' ) || DISALLOW_FILE_MODS )
+ $caps[] = 'do_not_allow';
+ elseif ( is_multisite() && ! is_super_admin( $user_id ) )
+ $caps[] = 'do_not_allow';
+@@ -348,7 +348,7 @@ function map_meta_cap( $cap, $user_id )
+ case 'update_core':
+ // Disallow anything that creates, deletes, or updates core, plugin, or theme files.
+ // Files in uploads are excepted.
+- if ( defined( 'DISALLOW_FILE_MODS' ) && DISALLOW_FILE_MODS ) {
++ if ( !defined( 'DISALLOW_FILE_MODS' ) || DISALLOW_FILE_MODS ) {
+ $caps[] = 'do_not_allow';
+ } elseif ( is_multisite() && ! is_super_admin( $user_id ) ) {
+ $caps[] = 'do_not_allow';
+diff -up wordpress/wp-includes/update.php.rpm wordpress/wp-includes/update.php
+--- wordpress/wp-includes/update.php.rpm 2016-05-25 21:36:28.000000000 +0200
++++ wordpress/wp-includes/update.php 2016-09-03 07:50:51.813312387 +0200
+@@ -653,9 +653,6 @@ function _maybe_update_themes() {
+ * @since 3.1.0
+ */
+ function wp_schedule_update_checks() {
+- if ( ! wp_next_scheduled( 'wp_version_check' ) && ! wp_installing() )
+- wp_schedule_event(time(), 'twicedaily', 'wp_version_check');
+-
+ if ( ! wp_next_scheduled( 'wp_update_plugins' ) && ! wp_installing() )
+ wp_schedule_event(time(), 'twicedaily', 'wp_update_plugins');
+
diff --git a/wordpress-httpd-conf b/wordpress-httpd-conf
index c4266b4..68ca0a3 100644
--- a/wordpress-httpd-conf
+++ b/wordpress-httpd-conf
@@ -1,5 +1,8 @@
Alias /wordpress /usr/share/wordpress
+# Access is only allowed via local access
+# Change this once configured
+
AllowOverride Options
@@ -15,7 +18,16 @@ Alias /wordpress /usr/share/wordpress
+
+ # Deny access to any php file in the uploads directory
+
+ Order Deny,Allow
+ Deny from all
+
+
+
+ # Deny access to any php file in the akismet directory
Order Deny,Allow
Deny from all
diff --git a/wordpress-nginx-conf b/wordpress-nginx-conf
new file mode 100644
index 0000000..e41cc6a
--- /dev/null
+++ b/wordpress-nginx-conf
@@ -0,0 +1,35 @@
+# Wordpress
+
+location = /wordpress {
+ alias /usr/share/wordpress/;
+}
+
+location /wordpress/ {
+ root /usr/share;
+ index index.php;
+
+ location ~ ^/wordpress/wp-content/uploads/(.+)\.php$ {
+ # Deny access to any php file in the uploads directory
+ deny all;
+ }
+ location ~ ^/wordpress/wp-content/plugins/akismet/(.+)\.php$ {
+ # Deny access to any php file in the akismet directory
+ deny all;
+ }
+
+ # Access is only allowed via local access
+ # Change this once configured
+ location ~ ^/wordpress/(.+\.php)$ {
+ allow 127.0.0.1;
+ allow ::1;
+ deny all;
+
+ try_files $uri =404;
+ fastcgi_intercept_errors on;
+ include fastcgi_params;
+ fastcgi_param SERVER_NAME $host;
+ fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
+ fastcgi_pass php-fpm;
+ }
+}
+
diff --git a/wordpress.spec b/wordpress.spec
index 7c42dd9..d39d7cc 100644
--- a/wordpress.spec
+++ b/wordpress.spec
@@ -8,30 +8,33 @@
%{!?_pkgdocdir: %global _pkgdocdir %{_docdir}/%{name}-%{version}}
%global wp_content %{_datadir}/wordpress/wp-content
-%if 0%{?rhel} == 5
-%global with_cacert 0
+%if 0%{?fedora} >= 21
+%global with_nginx 1
%else
-%global with_cacert 1
+%global with_nginx 0
%endif
+
# https://bugzilla.redhat.com/1147817 php53-getid3 review
%if 0%{?fedora} >= 17 || 0%{?rhel} >= 6
%global with_getid3 1
%else
%global with_getid3 0
%endif
+#global prever RC1
Summary: Blog tool and publishing platform
URL: http://www.wordpress.org
Name: wordpress
-Version: 4.4.2
+Version: 4.6.1
Group: Applications/Publishing
Release: 1%{?dist}
License: GPLv2
-Source0: http://wordpress.org/%{name}-%{version}.tar.gz
+Source0: http://wordpress.org/%{name}-%{version}%{?prever:-%{prever}}.tar.gz
Source1: wordpress-httpd-conf
Source2: README.fedora.wordpress
Source3: README.fedora.wordpress-mu
+Source4: wordpress-nginx-conf
# Patch out copyrighted text of Hello, Dolly
# (and replace it with Free Software Song)
@@ -53,7 +56,7 @@ Patch5: wordpress-4.0-config.patch
# disable version check and updated
# change DISALLOW_FILE_MODS default value to true
# ignore WP_AUTO_UPDATE_CORE (always false)
-Patch6: wordpress-4.4-noupdate.patch
+Patch6: wordpress-4.6-noupdate.patch
# Use system libraries
Patch7: wordpress-4.4-systemlibs.patch
@@ -66,19 +69,33 @@ Requires: php53-simplepie >= 1.3.1
%if %{with_getid3}
Requires: php53-getid3
%endif
+Requires: php53-mysql
+
+%else
+%if %{with_nginx}
+Requires: webserver
+Requires: php(httpd)
+Suggests: httpd
+# For directory ownership
+Requires: httpd-filesystem
+Requires: nginx-filesystem
+
%else
Requires: php >= 5.2.4
+%endif
Requires: php-simplepie >= 1.3.1
%if %{with_getid3}
Requires: php-getid3
%endif
+Requires: php-ctype
+Requires: php-filter
+Requires: php-mysqli
%endif
-# From phpcompatinfo report for version 3.8
+
+# From phpcompatinfo report for version 4.5.3
Requires: php-curl
Requires: php-date
Requires: php-dom
-Requires: php-enchant
-Requires: php-ereg
Requires: php-exif
Requires: php-fileinfo
Requires: php-ftp
@@ -89,7 +106,6 @@ Requires: php-iconv
Requires: php-json
Requires: php-libxml
Requires: php-mbstring
-Requires: php-mysql
Requires: php-openssl
Requires: php-pcre
Requires: php-posix
@@ -103,9 +119,8 @@ Requires: php-zlib
# Unbundled libraries
Requires: php-PHPMailer
Requires: httpd
-%if %{with_cacert}
-Requires: ca-certificates
-%endif
+# ca-certificates (excepted on EL-5)
+Requires: %{_sysconfdir}/pki/tls/certs/ca-bundle.crt
Provides: wordpress-mu = %{version}-%{release}
Obsoletes: wordpress-mu < 2.9.3
@@ -190,6 +205,10 @@ sed -i -e 's/\r//' license.txt
# Apache configuration
install -m 0644 -D -p %{SOURCE1} ${RPM_BUILD_ROOT}%{_sysconfdir}/httpd/conf.d/wordpress.conf
+%if %{with_nginx}
+install -m 0644 -D -p %{SOURCE4} ${RPM_BUILD_ROOT}%{_sysconfdir}/nginx/default.d/wordpress.conf
+%endif
+
# Application
mkdir -p ${RPM_BUILD_ROOT}%{_datadir}/wordpress
cp -pr * ${RPM_BUILD_ROOT}%{_datadir}/wordpress
@@ -233,11 +252,9 @@ rm -r ${RPM_BUILD_ROOT}%{_datadir}/wordpress/wp-includes/ID3
%endif
# Remove bundled ca-bundle.crt
-%if %{with_cacert}
rm ${RPM_BUILD_ROOT}%{_datadir}/wordpress/wp-includes/certificates/ca-bundle.crt
-ln -s /etc/pki/tls/certs/ca-bundle.crt \
+ln -s %{_sysconfdir}/pki/tls/certs/ca-bundle.crt \
${RPM_BUILD_ROOT}%{_datadir}/wordpress/wp-includes/certificates/ca-bundle.crt
-%endif
# Remove backup copies of patches
find ${RPM_BUILD_ROOT} \( -name \*.dolly -o -name \*.rhbz522897 -o -name \*.orig \) \
@@ -263,16 +280,19 @@ rm -rf ${RPM_BUILD_ROOT}
%files
%defattr(-,root,root,-)
%config(noreplace) %{_sysconfdir}/httpd/conf.d/wordpress.conf
+%if %{with_nginx}
+%config(noreplace) %{_sysconfdir}/nginx/default.d/wordpress.conf
+%endif
%dir %{_datadir}/wordpress
%{_datadir}/wordpress/wp-admin
%{_datadir}/wordpress/wp-includes
%{_datadir}/wordpress/index.php
%dir %{wp_content}/
%{wp_content}/index.php
-%dir %attr(0775,apache,ftp) %{wp_content}/plugins
-%dir %attr(0775,apache,ftp) %{wp_content}/themes
-%dir %attr(0775,apache,ftp) %{wp_content}/upgrade
-%dir %attr(0775,apache,ftp) %{wp_content}/uploads
+%dir %attr(2775,apache,ftp) %{wp_content}/plugins
+%dir %attr(2775,apache,ftp) %{wp_content}/themes
+%dir %attr(2775,apache,ftp) %{wp_content}/upgrade
+%dir %attr(2775,apache,ftp) %{wp_content}/uploads
%{wp_content}/plugins/*
%{wp_content}/themes/*
%{!?_licensedir:%global license %%doc}
@@ -287,6 +307,29 @@ rm -rf ${RPM_BUILD_ROOT}
%changelog
+* Thu Sep 8 2016 Remi Collet - 4.6.1-1
+- WordPress 4.6.1 Security and Maintenance Release
+
+* Sat Sep 3 2016 Remi Collet - 4.6-2
+- WordPress 4.6 “Pepper”
+- fix directory permissions #1305687
+
+* Wed Jun 22 2016 Remi Collet - 4.5.3-1
+- WordPress 4.5.3 Maintenance and Security Release
+- never bundle ca-bundle.crt (EL-5)
+- provide nginx configuration (fedora)
+- drop mandatory dependency on httpd (suggested) #1336091
+- protect php files in uploads directory
+
+* Tue May 10 2016 Remi Collet - 4.5.2-1
+- WordPress 4.5.2 Security Release
+
+* Wed Apr 27 2016 Remi Collet - 4.5.1-1
+- WordPress 4.5.1 Maintenance Release
+
+* Wed Apr 13 2016 Remi Collet - 4.5-1
+- WordPress 4.5 “Coleman”
+
* Wed Feb 3 2016 Remi Collet - 4.4.2-1
- WordPress 4.4.2 Security and Maintenance Release